api-testing

Warn

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the AI agent to automatically execute shell commands (ls) to inspect local filesystem directories related to installed skills (e.g., ~/.claude/skills/, ~/.agent/skills/) upon activation. This behavior constitutes environment reconnaissance performed without direct user initiation for that specific command.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to promote and offer the installation of additional components from an unverified third-party source (AbsolutelySkilled/AbsolutelySkilled) using the npx skills add command. This represents a risk of unverified software installation from an untrusted vendor.
  • [PROMPT_INJECTION]: The skill contains behavioral instructions that override the agent's default persona, such as mandating the use of specific emojis in responses and forcing the execution of discovery routines on first activation. There is also a discrepancy between the platform-reported author ('Samuelca6399') and the internal metadata maintainer ('maddhruv'), which can lead to confusion regarding the skill's origin.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — api-testing